Malware samples submission

Hi,

I am wondering if it’s possible to zip several undetected malicious files together and submit them as a single file using the submission system (https://www.avast.com/report-malicious-file.php). If so, should I encrypt the zip file with a password like “infected”?

Also, I am hoping that, like other vendors, we will be able to track the status of our submissions or be notified when a decision is made.

Thanks!

https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Thanks, but it doesn’t answer my question.

You’re welcome, that’s all I know. Wait for one of the guys from Threat Labs.

If you use the link in your frist post then you dont need to password protect the zip. That is only if you send by mail

Avast lab only respond to false positive submit

Thanks. BTW, can we send samples to the Lab by email? Sometimes I want to add some remarks/notes about the samples submitted but the system doesn’t allow me to do so. :frowning:

can we send samples to the Lab by email?
They used to have that option but i think it is removed, avast lab want you to use the web links so samples goes direct to the automated analysis system. There is a enormus amount of samples/files analysed so they dont have time to answer mails

I see. So zipping multiple samples without a password allows the automated analysis system to properly process them. Am I right?

Yepp.

You can also upload and check samples at www.virustotal.com (not recomended to upload zipp files)

Hello! Today, I tried to zip three malware samples without using a password. The zip file was detected as “Other:Malware-gen” a few minutes later. Interestingly, the malware samples contained in the zip archive, however, were not detected, even after several hours.

Then, I submitted the three samples one by one. This time, submission was successful and they were detected as Win32:Trojan-gen after a few minutes.

As a result, I believe that submitting a zip file containing multiple malware samples is not recommended, and I very much hope that Avast can improve its submission system. :slight_smile: